The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/7d7fe498-0aa3-4fa7-b560-610b42b2abed | third party advisory vdb entry exploit technical description |